Five of the iOS vulnerabilities last year were exploited in the wild.
https://www.securityweek.com/apple-patches-exploited-ios-vulnerability-in-old-iphones/
That's almost half the dozen zero-day vulnerabilities in iOS overall.
Apple's iOS 12.5.7 update patches CVE-2022-42856, an actively exploited vulnerability, in old iPhones and iPads.
Apple on Monday announced the release of iOS 12.5.7, which brings a patch
for an actively exploited vulnerability to old iPhones and iPads.
The tech giant released security updates for iOS, macOS and other products
on Monday to patch many vulnerabilities which were recently reported to
Apple by security researches, including a couple of WebKit flaws that can
lead to arbitrary code execution which Google researchers found in the
wild.
In addition to updates for the latest versions of its operating systems,
Apple announced the release of iOS 12.5.7, which patches CVE-2022-42856, a WebKit vulnerability that has been actively exploited by hackers against devices running iOS prior to the old vulnerable iOS version 15.1.
The new vulnerability, whose exploitation was first seen by Google's Threat Analysis Group (TAG), can be used for arbitrary code execution through specially crafted web content. Essentially the device is wide open to
hackers if the user visits a malicious web site and does nothing else.
Apple rolled out its first round of patches for CVE-2022-42856 in December 2022, when it released iOS 16.1.2. The fix was also included at the time in macOS Ventura 13.1, tvOS 16.2, Safari 16.2, and iOS and iPadOS 15.7.2.
Security updates for iOS 12 are increasingly rare, but Apple still releases patches when it needs to protect customers against such hugely advertised exploited flaws where users would likely complain it's Apple's fault.
There is still no public information from the tight-lipped Apple on the
attacks involving CVE-2022-42856 but according to data from Google, five of
the iOS vulnerabilities discovered in 2022 were exploited in the wild.
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)